KREMLIN browser-extension credential theft activity
Malware Activity
Summary
Hide ▲
Show ▼
The KREMLIN malware operation is using malicious browser extensions and multi-stage loaders to steal credentials and session tokens from Chrome and Edge users, increasing the risk of account takeover and browser-data theft. The activity has been active since at least May 2025 and is tied to a broader toolkit-delivery chain that includes loaders and installers. It also uses infrastructure-hiding and evasion techniques to sustain access and reduce disruption. The scope reaches at least 1,515 infected systems, most of them in Brazil.
Related Happenings
REF9334 Brazilian bank lure campaign using malicious browser extensions
Campaign
H score51
First: 15.09.2026 21:54
Last: 15.09.2026 21:54
Sources 1
How related:
"Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and Microsoft Edge."
About this happening:
The REF9334 campaign is actively using Brazilian bank lures to deploy a malicious browser extension, putting Chrome and Edge users at risk of credential theft....
REF9334 Brazilian bank lure campaign using malicious browser extensions
CampaignHow related: "Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and Microsoft Edge."
About this happening: The REF9334 campaign is actively using Brazilian bank lures to deploy a malicious browser extension, putting Chrome and Edge users at risk of credential theft....
Malicious Chrome and Edge browser-extension campaign
Campaign
H score16
First: 30.08.2026 17:17
Last: 30.08.2026 17:17
Sources 1
About this happening:
A malicious browser-extension campaign turned legitimate Google Chrome and Microsoft Edge add-ons into malware delivery vehicles, putting users at risk of crypto the...
Malicious Chrome and Edge browser-extension campaign
CampaignAbout this happening: A malicious browser-extension campaign turned legitimate Google Chrome and Microsoft Edge add-ons into malware delivery vehicles, putting users at risk of crypto the...
Jewelbug pairs espionage with industrial-scale cryptocurrency fraud
Threat Actor Meta
H score62
First: 13.08.2026 21:15
Last: 13.08.2026 21:15
Sources 1
About this happening:
Jewelbug is a China-linked threat actor operating a blended espionage and cryptocurrency fraud ecosystem. Broadcom’s Symantec and Carbon Black Threat Hunter...
Jewelbug pairs espionage with industrial-scale cryptocurrency fraud
Threat Actor MetaAbout this happening: Jewelbug is a China-linked threat actor operating a blended espionage and cryptocurrency fraud ecosystem. Broadcom’s Symantec and Carbon Black Threat Hunter...
Atlas RAT and related loaders deployed for remote access and credential theft
Malware Activity
H score33
First: 04.06.2026 00:45
Last: 04.06.2026 00:45
Sources 1
About this happening:
TA4922, a China-linked and likely financially motivated malware activity, has expanded beyond East Asia into Europe and Africa. The group uses Atlas RAT*...
Atlas RAT and related loaders deployed for remote access and credential theft
Malware ActivityAbout this happening: TA4922, a China-linked and likely financially motivated malware activity, has expanded beyond East Asia into Europe and Africa. The group uses Atlas RAT*...
Torg Grabber browser-extension theft activity
Malware Activity
H score36
First: 25.03.2026 20:32
Last: 25.03.2026 20:32
Sources 1
About this happening:
The Torg Grabber infostealer is actively stealing data from 850 browser extensions, including 728 cryptocurrency wallet extensions, which raises the risk of account ta...
Torg Grabber browser-extension theft activity
Malware ActivityAbout this happening: The Torg Grabber infostealer is actively stealing data from 850 browser extensions, including 728 cryptocurrency wallet extensions, which raises the risk of account ta...
Timeline
-
15.09.2026 21:54 1 articles · 2h ago
KREMLIN spans seven distinct campaigns
Campaign Scope UpdateBy June 16, 2025, the KREMLIN operation had already been attributed to seven distinct campaigns and was using malicious browser extensions alongside off-the-shelf Trojans such as Pulsar RAT and Remcos RAT.
Show sources
- KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens — thehackernews.com — 15.09.2026 21:54
-
15.09.2026 21:54 1 articles · 2h ago
KREMLIN moves endpoint rotation to Ethereum smart contracts
Technical Analysis UpdateOn May 19, 2026, KREMLIN shifted to Ethereum smart contracts to resolve volmira[.]site and zaviro[.]online, allowing the operation to rotate command-and-control endpoints and payload-hosting locations while also retrieving the AVSync System Inc. browser extension version 1.0.0 and ID ndpbidppejfanjbhfgjlohfanbfbklff.
Show sources
- KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens — thehackernews.com — 15.09.2026 21:54
-
15.09.2026 21:54 2 articles · 2h ago
Elastic Security Labs discloses REF9334 banking malware
Initial DisclosureOn September 15, 2026, Elastic Security Labs disclosed REF9334, a previously undocumented Brazilian banking malware operation active since at least May 2025 that uses lures impersonating Brazilian banks to install a malicious browser extension on Google Chrome and Microsoft Edge and steal credentials, session tokens, and sensitive data.
Show sources
- KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens — thehackernews.com — 15.09.2026 21:54
- KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens — thehackernews.com — 15.09.2026 21:54